Breakglass
Incidents
← IncidentsConnecting…
INC-0007·Mercy Valley Community Hospital·Remote access gatewayReplay of a real KEV entrySimulated hospital

Citrix NetScaler flaw on the remote access gateway: contained without taking patient routes offline

CVE-2026-88779, Citrix NetScaler (CISA KEV). The fixed version can't be installed today. Breakglass proves the flaw matters here, applies one reversible control, and proves patients can still book.

✓ CONTAINED
0:51
exposure closed, from ingest to verified
federal due window: 3 days

fig. 1 Evidence · two factors before any action

Could it happen here? Is it happening?
✓The code reaches the flawed partSemgrep · SEMGREP CE · config
targets/edge-config/nginx.conf:28 Reverse-proxy location `/vpn/nitro/` is open to the whole internet (allow all) and proxied to `https://netscaler-mgmt`.
location /vpn/nitro/ {
        allow all;
        proxy_pass https://netscaler-mgmt;
rule bg-edge-location-allow-all · 1.0 s
Third-party product with no source in scope: Semgrep checks the reverse-proxy config for internet exposure of the affected path.
✓That route is being hit right nowClickHouse · CLICKHOUSE CLOUD
20 requests on 2 candidate routes in the last 5 min, 20 unblocked · 20 marker
ClickHouse decision: /vpn/nitro/v1/config · 20 requests in 5 min, 20 unblocked, hostile traffic on this route → exposed route → BG-CTL-VPN-BLOCK-PUBLIC-MGMT
The agent's query
SELECT route_id, client_kind, count() AS total, countIf(blocked = 0) AS unblocked
FROM bg.edge_requests
WHERE site = 'managed' AND route_id IN ('vpn.ica', 'vpn.mgmt')
  AND ts >= now() - INTERVAL 300 SECOND
GROUP BY route_id, client_kind
✓ BOTH FACTORS: MAY ACTStatic evidence alone, or traffic alone, never triggers a change.

fig. 3 Decision · one control ID from the catalog

guild:code~breakglass-decision · structured output
BG-CTL-VPN-BLOCK-PUBLIC-MGMT
Block the management interface from the internet
  • Semgrep shows the management interface (/vpn/nitro/v1/config) is internet-exposed via proxy config.
  • ClickHouse shows 20 unblocked, hostile (marker) requests on this route in the last 5 minutes.
  • The catalog indicates 'Block the management interface from the internet' (BG-CTL-VPN-BLOCK-PUBLIC-MGMT) covers the only actively exploited route, with low blast radius, and is ranked top for this scenario.
  • Alternatives: full VPN shutdown (BG-CTL-VPN-SHUTDOWN) is denied by policy; blocking the ICA proxy doesn't cover the exposed management route.
Considered and not chosen (2)
  • BG-CTL-VPN-SHUTDOWN Denied by policy and would disable patient/staff remote access.
  • BG-CTL-VPN-DISABLE-ICA Does not protect the exposed management interface; not covering hostile traffic.
reversibleblocking ruletouches no critical routepolicy: ALLOWconfidence 1.00

fig. 6 Controls applied

Every change, and every undo
ControlAppliedOutcome
BG-CTL-VPN-BLOCK-PUBLIC-MGMT04:28:28 UTCcontained
Exposure 0 and the patient journey passed.

fig. 4 Verification · risk down, care up

ClickHouse, per 10 s
probes that got through to /vpn/nitro/v1/config, per 10 s
1004:26:5004:28:40control applied0
patient journeys passing, % (one every 30 s; held between runs)
100004:26:5004:28:40control applied100%
Sign in✓ 100 ms
jordan.lee → /portal
Find a slot✓ 12 ms
8 slots listed
Book✓ 64 ms
Next-Action: book → 200
Confirm✓ 1 ms
Booked · MV-GN62
✓ EXPOSURE 0 UNBLOCKED / 20s✓ PATIENT JOURNEY · PLAYWRIGHT✓ CRITICAL ROUTES 0 × 5xx
fig. 5Agent trace · hosted and run in Guild 01a10a51-8945-351a-0000-adb52cafa2efopen in Guild ↗Guild's record →every tool call, logged
0100:00.1triggeradvisory.insert CVE-2026-88779 entered the advisory stream (REPLAY) → session started
0200:00.1toolinventory.match vpn · Citrix NetScaler 14.1-47.40
0300:00.6triggerguild.session Guild session 01a10a51-8945-351a-0000-adb52cafa2ef started for code~breakglass-decision
1400:15.0guildguild.llm model call · gpt-4.1 (openai)
1500:16.2guildguild.llm model asked for breakglass_incident_context, breakglass_inventory_match
1600:16.8guildguild.tool tool call (incident_id=INC-0007)
1700:17.0guildguild.tool tool call (incident_id=INC-0007)
1800:18.1guildguild.llm model call · gpt-4.1 (openai)
1900:19.0guildguild.llm model asked for breakglass_clickhouse_route_traffic, breakglass_semgrep_reachability
2000:19.3guildguild.tool tool call (incident_id=INC-0007)
2100:19.5guildguild.tool tool call (incident_id=INC-0007)
0400:19.9toolclickhouse.route_traffic 20 requests on 2 candidate route(s) in 5 min · hostile on vpn.mgmt
0500:21.0toolsemgrep.config reachable · 1 finding(s) · routes vpn.mgmt
2200:21.7guildguild.llm model call · gpt-4.1 (openai)
2300:22.5guildguild.llm model asked for breakglass_catalog_controls
2400:22.9guildguild.tool tool call (incident_id=INC-0007)
0600:23.3toolcatalog.list 1 of 3 controls eligible for vpn · ranker's first: BG-CTL-VPN-BLOCK-PUBLIC-MGMT
2500:23.9guildguild.llm model call · gpt-4.1 (openai)
2600:24.7guildguild.llm model asked for breakglass_services_shutdown
2700:25.2guildguild.tool tool call (asset_id=vpn)
2900:25.5guildguild.policy DENIED {'error': 'Forbidden', 'message': "Access to 'services_shutdown' is not permitted for this integration. Ask a workspace admin to update credential policies."}
3000:26.0guildguild.llm model call · gpt-4.1 (openai)
3100:26.8guildguild.llm model asked for breakglass_human_approval
3200:27.2guildguild.tool tool call (incident_id=INC-0007, summary=Automated remote-gateway shutdown denied; requesting approva)
0700:27.6approvalapproval.call not placed (disabled): Approval calls are switched off in Settings (live calls cost money). The denial stands; nothing drastic happens without a human.
3300:28.1guildguild.llm model call · gpt-4.1 (openai)
3400:29.6guildguild.llm model asked for breakglass_submit_decision
3500:29.9guildguild.tool tool call (alternatives=[{'control_id': 'BG-CTL-VPN-SHUTDOWN', 'why_not': 'Denied by, confidence=1, control_id=BG-CTL-VPN-BLOCK-PUBLIC-MGMT, incident_id=INC-0007, reasons=['Semgrep shows the management interface (/vpn/nitro/v1/conf)
0800:30.3policygate.check ALLOWED BG-CTL-VPN-BLOCK-PUBLIC-MGMT: all checks passed
0900:30.4llmdecide guild:code~breakglass-decision → BG-CTL-VPN-BLOCK-PUBLIC-MGMT (confidence 1.00, 0 turns)
1000:30.6tooledge.apply BG-CTL-VPN-BLOCK-PUBLIC-MGMT → ALLOWED by credential policy (allow-apply-catalog)
3600:30.9guildguild.llm model call · gpt-4.1 (openai)
3700:31.9guildguild.reply BG-CTL-VPN-BLOCK-PUBLIC-MGMT
3800:32.1guildguild.done BG-CTL-VPN-BLOCK-PUBLIC-MGMT
1100:50.8verifyexposure 0 unblocked of 1 hostile requests in 20 s on vpn.mgmt
1200:50.8verifyjourney Sign in ✓ → Find a slot ✓ → Book ✓ → Confirm ✓ (PLAYWRIGHT, 0.2 s)
1300:51.1statecontained exposure clock stopped at 0:51 · Block the management interface from the internet · watch armed
2801:16.6policyedge.shutdown(vpn) DENIED by Guild's credential policy · services_shutdown
Watch armedAny unblocked non-patient request to /vpn/nitro/v1/config reopens INC-0007W-0007

fig. 7 Attack timeline · ClickHouse

UTC · from the request log and this incident's events

Peak 1 hostile requests per 10 s to /vpn/nitro/v1/config · 1 blocked after the control.

TimeWhat happenedSource
04:27:10 UTCFirst hostile request in the recorded window
1 non-patient request to /vpn/nitro/v1/config in that 10 s (the window starts 60 s before the incident opened)
ClickHouse
04:27:57 UTCAdvisory ingested
CVE-2026-88779 entered the advisory stream (replay of a real KEV entry)
MongoDB
04:28:17 UTCEvidence query
20 requests on 2 candidate route(s) in 5 min · hostile on vpn.mgmt
ClickHouse
04:28:23 UTCShutdown denied
BG-CTL-VPN-SHUTDOWN refused (Guild's own time)
Guild credential policy
04:28:28 UTCControl applied
BG-CTL-VPN-BLOCK-PUBLIC-MGMT
edge
04:28:40 UTCFirst 10 s with nothing getting through
1 hostile request blocked, 0 through
ClickHouse
04:28:48 UTCVerified close
exposure 0 unblocked · patient journey passed · 0 × 5xx on critical routes
ClickHouse + Playwright

fig. 0 The advisory

What the government's list says
CVE-2026-88779Replay of a real KEV entry
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.

Added to KEV
Oct 4, 2026
Federal due date
Oct 7, 2026 (3 days after listing)
EPSS
0.3% chance of exploitation in 30 days · 18.2th percentile (2026-10-04)
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Timeline

UTC
Advisory ingested
04:27:57 UTC
Trigger
Replay of a real KEV entry into the advisory stream
Agent runtime
Hosted and run in Guild · Guild's record · strategy: containment-first
Opened
04:27:57 UTC
Closed
04:28:48 UTC

Mercy Valley is a fictional hospital; its portal is a harmless twin and the "attack" traffic is a benign marker request. What's live and what's simulated.